CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2018-9073

    Last Modified: 21 Nov 2024

    Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.

    Published: 16 Nov 2018
    8.8
    High

    CVE-2018-19296

    Last Modified: 21 Nov 2024

    PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

    Published: 16 Nov 2018
    6.8
    Medium

    CVE-2019-6109

    Last Modified: 28 May 2026

    An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

    Published: 16 Nov 2018
    5.9
    Medium

    CVE-2019-6111

    Last Modified: 18 Dec 2025

    An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

    Published: 16 Nov 2018
    5.3
    Medium

    CVE-2018-20685

    Last Modified: 17 Dec 2025

    In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.

    Published: 16 Nov 2018
    4.2
    Medium

    CVE-2018-16859

    Last Modified: 21 Nov 2024

    Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.

    Published: 16 Nov 2018
    6.5
    Medium

    CVE-2018-18510

    Last Modified: 21 Nov 2024

    The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious site which links to these pages. This vulnerability affects Firefox < 64.

    Published: 16 Nov 2018
    6.8
    Medium

    CVE-2019-6110

    Last Modified: 18 Dec 2025

    In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

    Published: 16 Nov 2018
    6.1
    Medium

    CVE-2018-19301

    Last Modified: 21 Nov 2024

    tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later views the system log.

    Published: 15 Nov 2018
    6.5
    Medium

    CVE-2018-14934

    Last Modified: 21 Nov 2024

    The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authentication and subsequently record audio from the device microphone.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-14935

    Last Modified: 21 Nov 2024

    The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-16619

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager before 3.14 allows XSS.

    Published: 15 Nov 2018
    7.5
    High

    CVE-2018-16620

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.

    Published: 15 Nov 2018
    7.2
    High

    CVE-2018-16621

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.

    Published: 15 Nov 2018
    9.8
    Critical

    CVE-2018-8529

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-1643

    Last Modified: 21 Nov 2024

    The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144588

    Published: 15 Nov 2018
    8.1
    High

    CVE-2018-0673

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files via unspecified vectors.

    Published: 15 Nov 2018
    9.8
    Critical

    CVE-2018-0680

    Last Modified: 21 Nov 2024

    Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to read/send mail or change the configuration.

    Published: 15 Nov 2018
    9.8
    Critical

    CVE-2018-0682

    Last Modified: 21 Nov 2024

    Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not properly manage sessions, which allows remote attackers to read/send mail or change the configuration via unspecified vectors.

    Published: 15 Nov 2018
    9.8
    Critical

    CVE-2018-0683

    Last Modified: 21 Nov 2024

    Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via Cookie data.

    Published: 15 Nov 2018
    9.8
    Critical

    CVE-2018-0684

    Last Modified: 21 Nov 2024

    Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via multipart/form-data format data.

    Published: 15 Nov 2018
    8.8
    High

    CVE-2018-0685

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the Denbun POP version V3.3P R4.0 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via HTTP requests for mail search.

    Published: 15 Nov 2018
    8.8
    High

    CVE-2018-0686

    Last Modified: 21 Nov 2024

    Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote authenticated attackers to upload and execute any executable files via unspecified vectors.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-0687

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Nov 2018
    7.5
    High

    CVE-2018-0690

    Last Modified: 21 Nov 2024

    An unvalidated software update vulnerability in Music Center for PC version 1.0.02 and earlier could allow a man-in-the-middle attacker to tamper with an update file and inject executable files.

    Published: 15 Nov 2018
    7.8
    High

    CVE-2018-0692

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 15 Nov 2018
    7.5
    High

    CVE-2018-0693

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in FileZen V3.0.0 to V4.2.1 allows remote attackers to upload an arbitrary file in the specific directory in FileZen via unspecified vectors.

    Published: 15 Nov 2018
    9.8
    Critical

    CVE-2018-0694

    Last Modified: 21 Nov 2024

    FileZen V3.0.0 to V4.2.1 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-0695

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-0699

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in YukiWiki 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Nov 2018
    7.5
    High

    CVE-2018-0700

    Last Modified: 21 Nov 2024

    YukiWiki 2.1.3 and earlier does not process a particular request properly that may allow consumption of large amounts of CPU and memory resources and may result in causing a denial of service condition.

    Published: 15 Nov 2018
    7.5
    High

    CVE-2018-12543

    Last Modified: 21 Nov 2024

    In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert is triggered that should otherwise not be reachable and Mosquitto will exit.

    Published: 15 Nov 2018
    7.8
    High

    CVE-2018-16160

    Last Modified: 21 Nov 2024

    SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Windows PC.

    Published: 15 Nov 2018
    8.8
    High

    CVE-2018-16161

    Last Modified: 21 Nov 2024

    OpenDolphin 2.7.0 and earlier allows authenticated users to gain administrative privileges and perform unintended operations.

    Published: 15 Nov 2018
    8.8
    High

    CVE-2018-16162

    Last Modified: 21 Nov 2024

    OpenDolphin 2.7.0 and earlier allows authenticated attackers to obtain other users credentials such as a user ID and/or its password via unspecified vectors.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-0697

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Nov 2018
    6.5
    Medium

    CVE-2018-16163

    Last Modified: 21 Nov 2024

    OpenDolphin 2.7.0 and earlier allows authenticated attackers to bypass authentication to create and/or delete other users accounts via unspecified vectors.

    Published: 15 Nov 2018
    4.8
    Medium

    CVE-2018-0679

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00.06, Managed Ethernet switch FXC5428 firmware prior to version Ver1.00.07, Power over Ethernet (PoE) switch FXC5210PE/5218PE/5224PE firmware prior to version Ver1.00.14, and Wireless LAN router AE1021/AE1021PE firmware all versions) allows attacker with administrator rights to inject arbitrary web script or HTML via the administrative page.

    Published: 15 Nov 2018
    9.8
    Critical

    CVE-2018-0681

    Last Modified: 21 Nov 2024

    Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to login to the Management page and change the configuration.

    Published: 15 Nov 2018
    5.9
    Medium

    CVE-2018-0691

    Last Modified: 21 Nov 2024

    Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Nov 2018
    8.8
    High

    CVE-2018-0701

    Last Modified: 21 Nov 2024

    BlueStacks App Player (BlueStacks App Player for Windows 3.0.0 to 4.31.55, BlueStacks App Player for macOS 2.0.0 and later) allows an attacker on the same network segment to bypass access restriction to gain unauthorized access.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-12480

    Last Modified: 13 Feb 2025

    Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-19289

    Last Modified: 21 Nov 2024

    An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.

    Published: 15 Nov 2018
    6.5
    Medium

    CVE-2018-19291

    Last Modified: 21 Nov 2024

    An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-19288

    Last Modified: 21 Nov 2024

    Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-19286

    Last Modified: 21 Nov 2024

    The server in mubu note 2018-11-11 has XSS by configuring an account with a crafted name value (along with an arbitrary username value), and then creating and sharing a note.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-19287

    Last Modified: 21 Nov 2024

    XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.

    Published: 15 Nov 2018
    7
    High

    CVE-2018-18955

    Last Modified: 21 Nov 2024

    In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.

    Published: 15 Nov 2018
    6.1
    Medium

    CVE-2018-17960

    Last Modified: 21 Nov 2024

    CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.

    Published: 14 Nov 2018
    7.5
    High

    CVE-2018-19278

    Last Modified: 21 Nov 2024

    Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length.

    Published: 14 Nov 2018